Anthropic's New Enterprise Safeguards Keep Claude Activity Data on the Customer's Own Cloud
Anthropic built its new Enterprise Frontier Safeguards (EFS) program with more than 100 enterprise customers, including the banking-focused Analysis and Resilience Center for Systemic Risk (whose members include Goldman Sachs, Morgan Stanley, and Citigroup) plus partners like KPMG, Mastercard, Salesforce, and Comcast — and the program’s core trick is architectural rather than promotional. Under EFS, Claude activity data stays in the customer’s own AWS, Google Cloud, or Azure infrastructure under the customer’s own encryption keys, with automated pattern-based detection still catching serious misuse like cyberattacks or credential theft. When something is flagged, it routes directly to the customer’s own security team rather than to Anthropic personnel, preserving zero data retention on Anthropic’s side. Anthropic isn’t charging for EFS itself — customers pay their cloud provider as usual — and phased rollout begins this fall, with eligible customers getting interim zero-data-retention access to Fable 5 and Fable 5.1.
The problem EFS solves — how to monitor for misuse without retaining the data that misuse lives in — isn’t unique to Anthropic. OpenAI shipped a similar answer in August: Zero Data Retention extended to frontier models, plus a new Private Safety Processing capability that runs automated pattern-detection across related interactions while keeping the underlying content unreadable to OpenAI staff, sending only a narrow “this activity type was flagged” signal outward when something looks wrong. The two approaches converge on the same architecture — detect the pattern, keep the content local, escalate a signal instead of a transcript — because it’s the only way to reconcile a “we don’t retain your data” promise with a “we still need to catch attackers” requirement once agents are running long, multi-step tasks that only look suspicious in aggregate.
Salesforce’s Global Consent Manager, also announced this week, is the adjacent piece: a centralized hub meant to propagate a customer’s data-sharing opt-out instantly across CRM, data lakes, and AI workflows rather than letting it lag behind on some system nobody remembered to update. Read together, all three announcements point at the same underlying shift — enterprise AI buyers are now negotiating data architecture, not just feature lists, and vendors that can’t show where the data physically sits and who can see it are going to lose deals to ones that can.